Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Jest, a marketplace for messaging games, is challenging the app store status quo

After Zomato, Deepinder Goyal is back with a $54 million brain-monitoring bet

Pentagon moves to designate Anthropic as a supply chain risk

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Pentagon moves to designate Anthropic as a supply chain risk

    28 February 2026

    Anthropic CEO stands firm as Pentagon deadline looms

    27 February 2026

    Jack Dorsey just halved the size of Block’s employee base — and he says your company is next

    27 February 2026

    Salesforce CEO Marc Benioff: This isn’t our first SaaSpocalypse

    26 February 2026

    Gushwork is betting on AI prospecting for leads — and the first results are showing

    26 February 2026
  • Apps

    Spotify releases audiobook maps

    28 February 2026

    Bumble adds AI photo feedback and profile guidance tools

    27 February 2026

    Threads is testing a shortcut to quickly start DM conversations

    27 February 2026

    Instagram now alerts parents if their teen is looking for suicide or self-harm content

    26 February 2026

    Snapchat announces ‘The Snappys’, its first creator awards show

    26 February 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    3 days left: Save up to $680 on your ticket to Disrupt 2026

    25 February 2026

    More startups surpass $10M ARR in 3 months than ever before

    24 February 2026

    Stripe, PayPal Ventures Bet on India’s Xflow to Fix Cross-Border B2B Payments

    24 February 2026

    InScope raises $14.5M to solve financial reporting pain

    20 February 2026

    OpenAI deepens India push with Pine Labs fintech partnership

    19 February 2026
  • Hardware

    Last 24 hours to get Disrupt 2026 tickets at the lowest prices of the year

    27 February 2026

    Everything announced at Samsung’s Galaxy Unpacked event, including S26 smartphones, privacy screen and more

    26 February 2026

    Samsung introduces new display technology that adds a privacy screen to apps and notifications

    25 February 2026

    Oura launches a proprietary AI model focused on women’s health

    25 February 2026

    Spotify and Liquid Death are releasing a limited-edition speaker shaped like a … container?

    24 February 2026
  • Media & Entertainment

    Apple and Netflix team up to stream Formula 1 Canadian Grand Prix

    27 February 2026

    Netflix pulls out of bid for Warner Bros. Discovery, giving studios, HBO and CNN to Ellison-owned Paramount

    27 February 2026

    Book the best deals for Disrupt 2026 | TechCrunch

    26 February 2026

    Americans now listen to podcasts more often than talk radio, study shows

    25 February 2026

    Music producer ProducerAI joins Google Labs

    25 February 2026
  • Security

    CISA replaces deputy director after a difficult year on the job

    27 February 2026

    Cisco Says Hackers Are Exploiting Critical Flaw To Break Into Large Customer Networks By 2023

    26 February 2026

    US cybersecurity agency CISA reportedly in dire straits amid Trump cuts and layoffs

    26 February 2026

    Treasury sanctions Russian zero-day broker accused of buying holdings stolen from US defense contractor

    25 February 2026

    Former L3Harris Trenchant boss jailed for selling hacking tools to Russian broker

    25 February 2026
  • Startups

    Jest, a marketplace for messaging games, is challenging the app store status quo

    28 February 2026

    Superhuman bets on redesigned smart ring to win back US market after Oura controversy

    27 February 2026

    Trace raises $3 million to solve AI agent adoption in the enterprise

    27 February 2026

    How to avoid bad hires in early stage startups

    26 February 2026

    Apply to take the stage at Founder Summit 2026

    26 February 2026
  • Transportation

    Self-driving truck startup Einride raises $113M PIPE ahead of public debut

    27 February 2026

    It’s time to pull the plug on plug-in hybrids

    26 February 2026

    Harbinger acquires self-driving company Phantom AI

    26 February 2026

    Waymo robotaxis are now operating in 10 US cities

    25 February 2026

    Self-driving tech startup Wayve raises $1.2 billion from Nvidia, Uber and three automakers

    25 February 2026
  • Venture

    After Zomato, Deepinder Goyal is back with a $54 million brain-monitoring bet

    28 February 2026

    Dive into Boston’s startup ecosystem at Founder Summit 2026 | TechCrunch

    27 February 2026

    A VC and some big-name developers are trying to solve the open source funding problem, permanently

    27 February 2026

    Y Combinator grad and AI insurance brokerage Harper raises $47 million

    26 February 2026

    Anthropic acquires AI startup Vercept after Meta indicts one of its founders

    26 February 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Hundreds of Snowflake customer passwords found online linked to information-stealing malware
Security

Hundreds of Snowflake customer passwords found online linked to information-stealing malware

techtost.comBy techtost.com6 June 202408 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Hundreds Of Snowflake Customer Passwords Found Online Linked To Information Stealing
Share
Facebook Twitter LinkedIn Pinterest Email

Cloud data analytics company Snowflake is at the center of a recent wave of alleged data thefts as its enterprise customers try to figure out if their cloud data stores have been compromised.

Snowflake helps some of the world’s largest companies – including banks, healthcare providers and technology companies – store and analyze massive amounts of data, such as customer data, in the cloud.

Last week, Australian authorities sounded the alarm saying they were aware of “successful compromises of several companies using Snowflake environments,” without naming the companies. The hackers had claimed on a well-known cybercrime forum that they had stolen hundreds of millions of customer records from Santander Bank and Ticketmaster, two of Snowflake’s biggest customers. Santander confirmed database breach “hosted by a third party provider”, but does not name that provider. On Friday, Live Nation confirmed that its Ticketmaster subsidiary had been hacked and that the stolen database was hosted on Snowflake.

Snowflake recognized in a brief statement that it was aware of “potentially unauthorized access” to a “limited number” of customer accounts, without specifying which ones, but that it found no evidence of a direct breach of its systems. Instead, Snowflake called it a “targeted campaign targeting users with single-factor authentication” and that the hackers used “previously purchased or information-stealing malware” designed to scrape a user’s saved passwords from his computer.

Despite the sensitive data Snowflake maintains about its customers, Snowflake allows each customer to manage the security of their environment and does not automatically enroll or require its customers to use multi-factor authentication or MFA; according to the Snowflake customer documentation. Not enforcing the use of MFA appears to be how cybercriminals allegedly obtained massive amounts of data from some Snowflake customers, some of whom were setting up their environments without the added security measure.

Snowflake admitted that one of its own “demo” accounts was compromised because it was not protected beyond a username and password, but claimed that the account “did not contain any sensitive data”. It is unclear if this stolen demo account has any role in the recent breaches.

TechCrunch this week saw hundreds of alleged Snowflake customer credentials available online for cybercriminals to use as part of hacking campaigns, suggesting that the risk of Snowflake customer account compromises may be much greater than first known.

The credentials were stolen by malware infecting the computers of employees accessing their employer’s Snowflake environment.

Some of the credentials seen by TechCrunch appear to belong to employees at companies known to be customers of Snowflake, including Ticketmaster and Santander, among others. Employees with access to Snowflake include database engineers and data analysts, some of whom report their experience using Snowflake on their LinkedIn pages.

For its part, Snowflake has told customers to immediately enable MFA for their accounts. Until then, Snowflake accounts that don’t enforce the use of MFA to sign in leave their stored data at risk of being compromised by simple attacks like password theft and reuse.

How we checked the data

A source with knowledge of cybercriminal activity directed TechCrunch to a site where would-be attackers can search for lists of credentials stolen from various sources, such as stealing malware on someone’s computer or collecting from previous data breaches. (TechCrunch does not link to the site where stolen credentials are available, so as not to help bad actors.)

In total, TechCrunch has seen more than 500 credentials containing employee usernames and passwords, along with the web addresses of the login pages for the corresponding Snowflake environments.

The exposed credentials appear to be Snowflake environments owned by Santander, Ticketmaster, at least two pharmaceutical giants, a food delivery service, a public freshwater supplier and others. We also saw exposed usernames and passwords allegedly belonging to a former Snowflake employee.

TechCrunch is not naming the former employee because there is no evidence they did anything wrong. (It is ultimately the responsibility of both Snowflake and its customers to implement and enforce security policies that prevent intrusions resulting from the theft of employee credentials.)

We didn’t test for stolen usernames and passwords, as doing so would break the law. Therefore, it is unknown if the credentials are currently in use or if they directly led to account breaches or data theft. Instead, we worked to verify the authenticity of exposed credentials in other ways. This includes checking the individual login pages of the Snowflake environments exposed by the information-stealing malware, which was still active and connected at the time of writing.

The credentials we’ve seen include the employee’s email address (or username), their password, and the unique web address to log into their company’s Snowflake environment. When we checked the web addresses of Snowflake environments — which are often made up of random letters and numbers — we found that registered Snowflake customer login pages are publicly accessible, even if they are not searchable online.

TechCrunch has confirmed that the Snowflake environments correspond to the companies whose employee credentials were compromised. We were able to do this because every login page we checked had two separate options to log in.

One way to sign in is based on Okta, a single sign-on provider that allows Snowflake users to sign in with their company’s corporate credentials using MFA. In our checks, we found that these Snowflake login pages were redirected to the Live Nation (for Ticketmaster) and Santander login pages. We also found a set of credentials belonging to a Snowflake employee whose Okta login page still redirected to an internal Snowflake login page that no longer exists.

The other Snowflake login option allows the user to use only their Snowflake username and password, depending on whether the enterprise customer enforces MFA on the account, as described by Snowflake’s own support documentation. It is these credentials that appear to have been stolen by the malware stealing information from employees’ computers.

It’s unclear exactly when the employees’ credentials were stolen or how long they were online.

There is some evidence to suggest that several employees with access to their company’s Snowflake environments have previously had their computers compromised by information-stealing malware. According to an audit for the breach notification service Have I Been Pwned, several of the corporate email addresses used as usernames to access Snowflake environments were found in a recent data dump containing millions of stolen passwords is scraped from various Telegram channels used to share stolen passwords.

Snowflake spokeswoman Danica Stanczak declined to answer specific questions from TechCrunch, including whether any of its customers’ data was found in the Snowflake employee’s test account. In a statement, Snowflake said it is “suspending some user accounts where there is strong evidence of malicious activity.”

Snowflake added: “Under Snowflake’s shared responsibility model, customers are responsible for enforcing MFA with their users.” The spokesperson said that Snowflake is “looking at all options for enabling MFA, but we have not finalized any plans at this time.”

When reached by email, Live Nation spokeswoman Kaitlyn Henrich had no comment as of press time.

Santander did not respond to a request for comment.

The lack of MFA has resulted in massive breaches

Snowflake’s response so far leaves many questions unanswered and reveals a number of companies that are not reaping the benefits that MFA security provides.

What is clear is that Snowflake bears at least some responsibility for not requiring its users to enable security mode, and now bears the brunt of it — along with its customers.

The data breach at Ticketmaster reportedly involved more than 560 million customer records, according to cybercriminals who advertised the data online. (Live Nation would not comment on how many customers are affected by the breach.) If proven, Ticketmaster would be the largest data breach in the US so far this year and one of the largest in recent history.

Snowflake is the latest company in a series of high-profile security incidents and major data breaches caused by a lack of MFA.

Last year, cybercriminals deleted about 6.9 million customer records from 23andMe accounts that weren’t protected without MFA, prompting the genetic testing company — and its competitors — to require users to enable MFA by default to prevent a repeat attack.

And earlier this year, UnitedHealth-owned health tech giant Change Healthcare admitted hackers broke into its systems and stole massive amounts of sensitive health data from a system not protected by MFA. The healthcare giant has not yet said how many people had their information breached, but said it was likely to affect a “significant percentage of people in America”.


Do you know more about Snowflake account hacks? Getting in touch. To contact this reporter, please contact Signal and WhatsApp at +1 646-755-8849 or via email. You can also send files and documents via SecureDrop.

cloud customer cyber security data breach hundreds informationstealing linked malware online passwords Santander Snowflake TicketMaster
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDealt turns retailers into service providers and proves that pivots sometimes work
Next Article Amazon buys Indian video streaming service MX Player
bhanuprakash.cg
techtost.com
  • Website

Related Posts

CISA replaces deputy director after a difficult year on the job

27 February 2026

Cisco Says Hackers Are Exploiting Critical Flaw To Break Into Large Customer Networks By 2023

26 February 2026

US cybersecurity agency CISA reportedly in dire straits amid Trump cuts and layoffs

26 February 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Jest, a marketplace for messaging games, is challenging the app store status quo

28 February 2026

After Zomato, Deepinder Goyal is back with a $54 million brain-monitoring bet

28 February 2026

Pentagon moves to designate Anthropic as a supply chain risk

28 February 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

3 days left: Save up to $680 on your ticket to Disrupt 2026

25 February 2026

More startups surpass $10M ARR in 3 months than ever before

24 February 2026

Stripe, PayPal Ventures Bet on India’s Xflow to Fix Cross-Border B2B Payments

24 February 2026
Startups

Jest, a marketplace for messaging games, is challenging the app store status quo

Superhuman bets on redesigned smart ring to win back US market after Oura controversy

Trace raises $3 million to solve AI agent adoption in the enterprise

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.